思远(SiYuan)在 v3.8.1 之前版本中存在一个存储型跨站脚本(XSS)漏洞,位于 函数中。该漏洞的成因是:包名称和笔记本名称未经过转义处理,直接被插入到 赋值中。攻击者可以提交恶意的应用市场(Bazaar)包,在其名称字段中嵌入 HTML/脚本载荷。当用户卸载这些包或解锁加密笔记本时,这些脚本会在用户的浏览器中执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| siyuan-note | siyuan | 0 ~ 3.8.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82654 | 8.9 HIGH | SiYuan before v3.8.1 Stored XSS via block name |
| CVE-2026-82649 | 7.0 HIGH | SiYuan before 3.8.1 Local Privilege Escalation via Uncontrolled Search Path |
| CVE-2026-82652 | 5.3 MEDIUM | SiYuan before v3.8.1 Information Disclosure via Publish Access |
| CVE-2026-82651 | 4.9 MEDIUM | SiYuan before v3.8.1 Missing Authorization via /history and /repo/diff |
| CVE-2026-82650 | 4.4 MEDIUM | SiYuan before v3.8.1 Path Traversal via /api/template/render |
No comments yet